PT-2002-2119 · Mantis · Mantis

Publicado

2002-10-04

·

Atualizado

2017-10-10

·

CVE-2002-1116

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Mantis versions 0.17.4a and earlier
Description: The issue concerns the "View Bugs" page, specifically the view all bug page.php file, which incorrectly includes summaries of private bugs. This affects users without access to any projects, potentially exposing sensitive information.
Recommendations: For Mantis versions 0.17.4a and earlier, as a temporary workaround, consider restricting access to the view all bug page.php file until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1116
DSA-161

Produtos afetados

Mantis